# Kibana 6.4 chracter limit?

**URL:** <https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446>\
**Category:** Kibana\
**Created:** [September 13, 2018, 12:24pm UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446 "2018-09-13T12:24:37Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ufkun\_Karaman](https://avatars.discourse-cdn.com/v4/letter/u/fbc32d/32.png) [@Ufkun\_Karaman](https://discuss.elastic.co/u/Ufkun_Karaman)\
**Post date:** [September 13, 2018, 12:24pm UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/1 "2018-09-13T12:24:37Z")

</div>

I use elk 6.4  
How can I solve the problem ? ( The problem is missing value ??)

 ![Screenshot%20at%202018-09-14%2011-40-31](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8ae8cbd67e1967534110c1fed8121e8c7c3a9bba.png)

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [September 13, 2018, 2:50pm UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/2 "2018-09-13T14:50:56Z")

</div>

Can you verify that 'Missing' is coming from Kibana and not the elasticsearch document? What's your workflow used to ingest these documents?

I believe Kibana will use a hyphen if the field is empty.

---

<div class="post-metadata">

**Author:** ![Ufkun\_Karaman](https://avatars.discourse-cdn.com/v4/letter/u/fbc32d/32.png) [@Ufkun\_Karaman](https://discuss.elastic.co/u/Ufkun_Karaman)\
**Post date:** [September 14, 2018, 6:43am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/3 "2018-09-14T06:43:10Z")

</div>

![Screenshot%20at%202018-09-14%2009-12-46](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9bfc9042ad86580a8d0285b1150492d7c59708a.png)

My system =\> (syslog (5000 port udp) =\> logstash =\> elasticsearch =\> kibana )  
I parse message on logstash.  
if ı want to send 300 characters log , I can see kibana's discovery or kibana's dev tool  
but if ı look this info on kibana's visualize , ı can not see ( ı see "missing") (???)

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [September 14, 2018, 2:49pm UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/4 "2018-09-14T14:49:01Z")

</div>

My apologies, I had to do some research. The "Missing" text is roughly saying we have a sub bucket that is empty. I'm guessing this is related to the number of terms aggregations we're doing, it's splitting the data up several times.

Can you add some info about how you want this data table to look? If it's a document level view creating this from discover instead of visualize may be what we're looking for

---

<div class="post-metadata">

**Author:** ![jonsmiteeww](https://avatars.discourse-cdn.com/v4/letter/j/c4cdca/32.png) [@jonsmiteeww](https://discuss.elastic.co/u/jonsmiteeww)\
**Post date:** [September 14, 2018, 7:05pm UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/5 "2018-09-14T19:05:19Z")

</div>

what version of Kibana are you on? what happens when you remove the offending visualization?

---

<div class="post-metadata">

**Author:** ![Ufkun\_Karaman](https://avatars.discourse-cdn.com/v4/letter/u/fbc32d/32.png) [@Ufkun\_Karaman](https://discuss.elastic.co/u/Ufkun_Karaman)\
**Post date:** [September 18, 2018, 5:50am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/6 "2018-09-18T05:50:53Z")

</div>

My table like - syslog\_priority -timestamp -syslog\_hostnames -syslog\_program- syslog\_process- syslog\_massage\_id- syslog\_message

logstash parsing like that =\>  
match =\> ["message","%{POSINT:syslog\_priority} %{TIMESTAMP\_ISO8601:syslog\_time} %{SYSLOGPROG:syslog\_program} %{SYSLOGHOST:syslog\_hostname} %{NOTSPACE:syslog\_process} %{NOTSPACE:syslog\_massage\_id} %{NOTSPACE:syslog\_level} %{GREEDYDATA:syslog\_message}"]

---

<div class="post-metadata">

**Author:** ![Ufkun\_Karaman](https://avatars.discourse-cdn.com/v4/letter/u/fbc32d/32.png) [@Ufkun\_Karaman](https://discuss.elastic.co/u/Ufkun_Karaman)\
**Post date:** [September 18, 2018, 8:53am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/7 "2018-09-18T08:53:57Z")

</div>

I use Kibana version -\> 6.4.0 . And ı try Kibana -\> 6.2.4 .I take same result.The problem is that the "missing" error. The aim is to solve the "missing" error .and show those lost data.(missing error seems if the characters numbers are 300 (if the characters numbers are 200 , data will seen) )

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [September 21, 2018, 3:21am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/8 "2018-09-21T03:21:44Z")

</div>

Hi Ufkun, I think the best place for this is from discover and it should be able to achieve what you want. When you hover over a field on the left hand side of the page, you can add the column. Saving the search from discover will let you add this table to a dashboard.

Do you think this will work for you?

---

<div class="post-metadata">

**Author:** ![Ufkun\_Karaman](https://avatars.discourse-cdn.com/v4/letter/u/fbc32d/32.png) [@Ufkun\_Karaman](https://discuss.elastic.co/u/Ufkun_Karaman)\
**Post date:** [October 5, 2018, 6:14am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/9 "2018-10-05T06:14:47Z")

</div>

Thank your answer.At the moment your answer is best answer but not solution.I will work here .Thanks for helping

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2018, 6:14am UTC](https://discuss.elastic.co/t/kibana-6-4-chracter-limit/148446/10 "2018-11-02T06:14:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
